Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

grafana/hackathon-12-action-stat

grafana/hackathon-12-action-stat

3/10
microsoft/vstest-action

microsoft/vstest-action

GitHub Action equivalent to the Azure DevOps VS Test Task

4/10
rapidsai/shared-actions/telemetry-dispatch-write-summary

rapidsai/shared-actions/telemetry-dispatch-write-summary

5/10
linaro-its/merge-test-branch

linaro-its/merge-test-branch

1/10
unfor19/install-aws-cli-action

unfor19/install-aws-cli-action

Install AWS CLI on a GitHub Actions Linux host

5/10
rudderlabs/rudder-sdk-kotlin/.github/actions/build-check

rudderlabs/rudder-sdk-kotlin/.github/actions/build-check

Kotlin Android SDK and Kotlin JVM for RudderStack - the Customer Data Platform for Developers.

6/10
PaulHatch/semantic-version

PaulHatch/semantic-version

A GitHub Action to generate semantic version from a git repository's commit history.

5/10
microsoft/psscriptanalyzer-action

microsoft/psscriptanalyzer-action

GitHub Action to run PSScriptAnalyzer to your repository and produce a SARIF file

6/10
os-climate/osc-github-devops/.github/actions/semantic-tag-production-action

os-climate/osc-github-devops/.github/actions/semantic-tag-production-action

Template Python project, common tests, GitHub Actions/Workflows, linting tools

5/10
flathub-infra/flatpak-github-actions/flatpak-builder

flathub-infra/flatpak-github-actions/flatpak-builder

2/10
blackduck-inc/black-duck-security-scan

blackduck-inc/black-duck-security-scan

Black Duck Security Action consuming Black Duck scanning tools

5/10
step-security/npm-get-version-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/npm-get-version-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

This Action scans for a package.json file and reads the version number from that. Secure drop-in replacement for martinbeentjes/npm-get-version-action.

10/10
step-security/delete-deployment-environment/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/delete-deployment-environment/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

GitHub action to remove an environment and it's deployments. Secure drop-in replacement for strumwolf/delete-deployment-environment.

10/10
wow-actions/auto-comment

wow-actions/auto-comment

💬 Automatically comment issues or PRs on events triggered

2/10
actions/labeler

actions/labeler

An action for automatically labelling pull requests

6/10
clowdhaus/aws-lambda-code-signing-action

clowdhaus/aws-lambda-code-signing-action

GitHub action which uses AWS Code Signer to sign ✍🏼 AWS Lambda artifacts 📦 from your pipeline

5/10
pytorch/multipy/test-infra/.github/actions/setup-ssh

pytorch/multipy/test-infra/.github/actions/setup-ssh

torch::deploy (multipy for non-torch uses) is a system that lets you get around the GIL problem by running multiple Python interpreters in a single C++ process.

3/10
grafana/grafana-async-query-data-js/actions/commands

grafana/grafana-async-query-data-js/actions/commands

8/10
NVIDIA/nvbench/nvbench/.github/actions/configure_cccl_sccache

NVIDIA/nvbench/nvbench/.github/actions/configure_cccl_sccache

CUDA Kernel Benchmarking Library

5/10
sredevopsorg/metabase/.github/actions/prepare-frontend

sredevopsorg/metabase/.github/actions/prepare-frontend

The simplest, fastest way to get business intelligence and analytics to everyone in your company :yum:

3/10